Functional Safety Software Image Integrity Verifier
Abstract
Various embodiments include methods and devices for generating and verifying a software image with a safety feature. Embodiments may include generating a safety feature from a first software image, and generating a second software image including the safety feature. Embodiments may include, retrieving a first safety feature from a software image with the first safety feature, calculating a second safety feature based on information relating to the software image with the first safety feature, comparing the first safety feature and the second safety feature, and verifying safety of the software image with the first safety feature in response to the first safety feature matching with the second safety feature. The methods and devices may be implemented in compliance with functional safety standards, such as ISO 26262 functional safety standards and, in compliance with Automotive Safety Integrity Level (ASIL) requirements, such as ASIL-D and/or ASIL QM requirements.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of generating a software image, comprising:
generating a safety feature from a first software image; and generating a second software image including the safety feature.
2 . The method of claim 1 , wherein generating the second software image including the safety feature comprises embedding the safety feature in the first software image.
3 . The method of claim 1 , wherein:
generating the safety feature from the first software image comprises:
retrieving information relating to segments of the first software image;
calculating an error detection code based on the information relating to
the segments of the first software image producing a checksum value; and generating the second software image including the safety feature comprises generating the second software image including the checksum value.
4 . The method of claim 1 , wherein generating the second software image including the safety feature comprises:
generating a software image verifier (SWIV) header; generating a SWIV segment including the safety feature; and generating the second software image including the SWIV header and the SWIV segment.
5 . The method of claim 1 , wherein:
generating the safety feature from the first software image comprises generating the safety feature via a functional safety standard compliant module; and generating the second software image including the safety feature comprises generating the second software image including the safety feature via the functional safety standard compliant module.
6 . The method of claim 5 , wherein the functional safety standard compliant module is an ISO 26262 functional safety standard compliant module.
7 . The method of claim 5 , wherein the functional safety standard compliant module is an Automotive Safety Integrity Level (ASIL)-QM functional safety standard compliant module.
8 . A computing device, comprising:
a processing device configured with processing device-executable instructions to:
generate a safety feature from a first software image; and
generate a second software image including the safety feature.
9 . The computing device of claim 8 , wherein the processing device is further configured with processing device-executable instructions to embed the safety feature in the first software image.
10 . The computing device of claim 8 , wherein the processing device is further configured with processing device-executable instructions to generate the safety feature from the first software image by:
retrieving information relating to segments of the first software image; calculating an error detection code based on the information relating to the segments of the first software image producing a checksum value; and generating the second software image including the safety feature comprises generating the second software image including the checksum value.
11 . The computing device of claim 8 , wherein the processing device is further configured with processing device-executable instructions to generate the second software image including the safety feature by:
generating a software image verifier (SWIV) header; generating a SWIV segment including the safety feature; and generating the second software image including the SWIV header and the SWIV segment.
12 . The computing device of claim 8 , wherein the processing device is further configured with processing device-executable instructions to:
generate the safety feature from the first software image via a functional safety standard compliant module; and generate the second software image including the safety feature via the functional safety standard compliant module.
13 . The computing device of claim 12 , wherein the functional safety standard compliant module is an ISO 26262 functional safety standard compliant module.
14 . The computing device of claim 12 , wherein the functional safety standard compliant module is an Automotive Safety Integrity Level (ASIL)-QM functional safety standard compliant module.
15 . A method of verifying a software image, comprising:
retrieving a first safety feature from a software image with the first safety feature; calculating a second safety feature based on information relating to the software image with the first safety feature; comparing the first safety feature and the second safety feature; and verifying safety of the software image with the first safety feature in response to the first safety feature matching the second safety feature.
16 . The method of claim 15 , wherein retrieving the first safety feature from the software image with the first safety feature comprises retrieving the first safety feature from a software image verifier (SWIV) segment of the software image with the first safety feature.
17 . The method of claim 15 , further comprising:
retrieving the information relating to the software image with the first safety feature from the software image with the first safety feature; generating a software image verifier (SWIV) context including the first safety feature and the information relating to the software image with the first safety feature; retrieving the information relating to the software image with the first safety feature from the SWIV context, wherein calculating the second safety feature based on the information relating to the software image with the first safety feature comprises calculating the second safety feature based on the information relating to the software image retrieved from the SWIV context; and retrieving the first safety feature from the SWIV context, wherein comparing the first safety feature and the second safety feature comprises comparing the first safety feature retrieved from the SWIV context and the second safety feature.
18 . The method of claim 15 , further comprising:
loading the software image with the first safety feature to a volatile memory, wherein retrieving the first safety feature from the software image with the first safety feature, calculating the second safety feature based on the information relating to the software image with the first safety feature, comparing the first safety feature and the second safety feature, and verifying the safety of the software image with the first safety feature in response to the first safety feature matching with the second safety feature occur following loading the software image with the first safety feature to the volatile memory.
19 . The method of claim 15 , wherein retrieving the first safety feature from the software image with the first safety feature, calculating the second safety feature based on the information relating to the software image with the first safety feature, comparing the first safety feature and the second safety feature, and verifying the safety of the software image with the first safety feature in response to the first safety feature matching with the second safety feature occur prior to each execution of the software image with the first safety feature.
20 . The method of claim 15 , wherein:
retrieving the first safety feature from the software image with the first safety feature comprises retrieving the first safety feature from the software image with the first safety feature via a functional safety standard compliant module; calculating the second safety feature based on information relating to the software image with the first safety feature comprises calculating the second safety feature based on the information relating to the software image with the first safety feature via the functional safety standard compliant module; comparing the first safety feature and the second safety feature comprises comparing the first safety feature and the second safety feature via the functional safety standard compliant module; and verifying safety of the software image with the first safety feature in response to the first safety feature matching with the second safety feature comprises verifying the safety of the software image with the first safety feature via the functional safety standard compliant module.
21 . The method of claim 20 , wherein the functional safety standard compliant module is an ISO 26262 functional safety standard compliant module.
22 . The method of claim 20 , wherein the functional safety standard compliant module is an Automotive Safety Integrity Level (ASIL)-D functional safety standard in compliant module.
23 . A computing device, comprising:
a processing device configured with processing device-executable instructions to: retrieve a first safety feature from a software image with the first safety feature; calculate a second safety feature based on information relating to the software image with the first safety feature; compare the first safety feature and the second safety feature; and verify safety of the software image with the first safety feature in response to the first safety feature matching the second safety feature.
24 . The computing device of claim 23 , wherein the processing device is further configured with processing device-executable instructions to retrieve the first safety feature from a software image verifier (SWIV) segment of the software image with the first safety feature.
25 . The computing device of claim 23 , wherein the processing device is further configured with processing device-executable instructions to:
retrieve the information relating to the software image with the first safety feature from the software image with the first safety feature; generate a software image verifier (SWIV) context including the first safety feature and the information relating to the software image with the first safety feature; retrieve the information relating to the software image with the first safety feature from the SWIV context, wherein calculating the second safety feature based on the information relating to the software image with the first safety feature comprises calculating the second safety feature based on the information relating to the software image retrieved from the SWIV context; and retrieve the first safety feature from the SWIV context, wherein comparing the first safety feature and the second safety feature comprises comparing the first safety feature retrieved from the SWIV context and the second safety feature.
26 . The computing device of claim 23 , wherein the processing device is further configured with processing device-executable instructions to:
load the software image with the first safety feature to a volatile memory; and retrieve the first safety feature from the software image with the first safety feature, calculate the second safety feature based on the information relating to the software image with the first safety feature, compare the first safety feature and the second safety feature, and verify the safety of the software image with the first safety feature in response to the first safety feature matching with the second safety feature following loading the software image with the first safety feature to the volatile memory.
27 . The computing device of claim 23 , wherein the processing device is further configured with processing device-executable instructions to retrieve the first safety feature from the software image with the first safety feature, calculate the second safety feature based on the information relating to the software image with the first safety feature, compare the first safety feature and the second safety feature, and verify the safety of the software image with the first safety feature in response to the first safety feature matching with the second safety feature prior to each execution of the software image with the first safety feature.
28 . The computing device of claim 23 , wherein the processing device is further configured with processing device-executable instructions to:
retrieve the first safety feature from the software image with the first safety feature via a functional safety standard compliant module; calculate the second safety feature based on information relating to the software image with the first safety feature via the functional safety standard compliant module; compare the first safety feature and the second safety feature via the functional safety standard compliant module; and verify the safety of the software image with the first safety feature via the functional safety standard compliant module.
29 . The computing device of claim 28 , wherein the functional safety standard compliant module is an ISO 26262 functional safety standard compliant module.
30 . The computing device of claim 28 , wherein the functional safety standard compliant module is an Automotive Safety Integrity Level (ASIL)-D functional safety standard compliant module.Join the waitlist — get patent alerts
Track US2024289098A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.